ThunderX

Aliases: Ranzy Locker

First seen
2021-06-15 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:44:10

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Targeted regions: country_code:us country_code:de country_code:fr

Context

ThunderX, also known as Ranzy Locker, is a strain of ransomware that targets organizations in various sectors. It typically encrypts the victim's files and demands a ransom for decryption keys.

Detection coverage

  • 2 YARA rules

Detection rules

  • ARKBIRD_SOLG_Ran_Ranzy_Locker_Nov_2020_1 (yara-rule)
  • MALPEDIA_Win_Thunderx_Auto (yara-rule)

Reports & references

  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
  • cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
  • Mandiant — Chasing Avaddon Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Thunderx (report)
  • labs.sentinelone.com — Ranzy Ransomware Better Encryption Among New Features Of Thunderx Derivative (report)
  • picussecurity.com — A Detailed Walkthrough Of Ranzy Locker Ransomware Ttps (report)
  • id-ransomware.blogspot.com — Thunderx Ransomware (report)
  • ic3.gov — 211026 (report)
  • bleepingcomputer.com — Thunderx Ransomware Rebrands As Ranzy Locker Adds Data Leak Site (report)

External references